GeoServer Flaw Draws Fast Probing, Possible Server Takeover

Researchers saw hundreds of probing attempts within hours of public disclosure against GeoServer’s unauthenticated SQL injection flaw in jsonArrayContains. The issue is still unpatched, and the software is used across government, defense, education, engineering, and technology shops. The bug lets an unauthenticated request run SQL against GeoServer’s database. If that database account has administrator rights on Microsoft SQL Server, the injected SQL can spill from the database into commands on the host itself, turning what looks like data tampering into possible server compromise. For internet-exposed GeoServer deployments, the near-term risk is opportunistic targeting before a fix exists, especially where the backend runs with more privilege than it needs. If those attempts progress, logs may be the only record left behind.

Part of the PlainSec briefing for 2026-08-14

Every edition of this story: GeoServer Flaw Draws Fast Probing, Possible Server Takeover

Sources